Posts

Bluetooth Attacks

Bluetooth Attack Types 1. Bluejacking The attacker sends an unsolicited message to a nearby device. The type of message can be an image or text. 2. Blueborne This type of attack is a virus that is spread through the air. It allows the attacker to take full control of the target device. The target device doesn’t have to be in discoverable mode for the attack to be successful. 3. Bluesnarfing An attacker accesses a Bluetooth device to steal contact lists, text messages, calendars, and emails. The attackers use tools such as obexftp and hcitool. 4. Bluebugging This type of attack allows the attacker to enable call forwarding on the target device, the ability to listen in all calls, and can send messages.

Kerberos

KERBEROS Kerberos is an authentication protocol Kerberos provides SSO (Single Sign-On) Uses Port 88 TCP or UDP KDC (Key Distribution Center) uses 2 services: Authentication Service and a Ticket Granting Service Authentication Service handles authenticating user login requests The AS issues a TGT (Ticket Granting Ticket) To access any resource within the domain the client quests a Service Ticket The TGS (Ticket Granting Service) issues the Service Ticket to the client so they can access the resource TGT's are uniques to Kerberos only By default, the client and the Kerberos server have to be within a 5-minute window of each other for authentication to succeed.  Kerberos provides mutual authentication as the server authenticates to the client. Kerberos prevents eavesdropping and MITM attacks. (Man-In-The-Middle)

AAA Services (Authentication, Authorization, and Accounting)

AAA Services RADIUS: Remote Authentication Dial-in User Service Port 1812 UDP for authentication Port 1813 TCP for accounting WPA Enterprise / WPA2 Enterprise both require a RADIUS server. RADIUS clients are also referred to as 802.1x clients. RADIUS is a client/server protocol. Communication between the client and the RADIUS server uses UDP RADIUS is vendor-neutral Only encrypts the passwords Diameter Uses TCP for communication between client and server. Considered to be an improvement over RADIUS. Diameter also works with VoIP Used for both local and remote access TACACS+: Terminal Access Controller Access-Control System Plus TACACS+ provides a more advanced AAA Three different servers, Authentication, Authorization, Accounting Communicates over TCP Uses Port 49 TCP Manages routers and switches (Network infrastructure devices) Encrypts the entire packet TACACS+ is a proprietary protocol

C - I - A: Confidentiality - Integrity - Availability

CIA  Confidentiality: Making certain information (data) is only viewable by certain people. 1. Encryption is the main method for confidentiality. Whether it is file encryption, full disk encryption, or full device encryption for mobile devices. The user needing to read the information would need a decryption key to decipher the encryption first.  2. ACL (Access Control Lists) is another method of providing confidentiality. This is not as secure as using encryption. There are different access control methods such as MAC (Mandatory Access Control), DAC ( Discretionary Access Control), Role-BAC (Role-Based Access Control), Rule-BAC (Rule-Based Access Control), and ABAC (Attribute Access Control). These methods and examples will be discussed in a different post. 3. Steganography: With this method, you could hide a document inside of another document, inside a photo, video file, or audio file. The carrier (the file used as the hiding method has...

Security Controls - Preventive

Preventive What you are trying to do is prevent some form of security breach/incident. Change management: Making sure that there or no outages that were not planned. Being as I work as an IT administrator, it's easy to want to make changes on the fly. The first step in this process is to submit the change plan and get approval. These changes can be network configuration changes or changing to a more current operating system. We need to plan, test, and practice before attempting the changes to reduce the chances of downtime on a production network. Security awareness and training:   Make users aware of social engineering attacks, email, and social network best practices. Once the users are aware of the tactics a social engineer might use, the less chance of them being fooled into revealing the passwords. For example, Microsoft is not going to call you and ask for your password, which is a threat actor attempting to social engineer you. Disabling Accounts: Hav...

RAID (Redundant Array of Independent Disks)

Image
RAID (Redundant Array of Independent Disks) RAID 0: RAID 0 provides no fault tolerance or redundancy. Requires a minimum of 2 disks. The information is spread across each drive (for example: as it fills one block then adds data to the next sequential block).  RAID 0 is striping with no parity. If one drive fails, all the information is lost, unless you have a backup of the data. This form of RAID is used for performance, multiple heads reading/writing at the same time. Both drives should be of the same size and speed. If you have two 320 GB drives, theoretically you would have 640 GB of storage space using this configuration.  RAID 0 is best used for video and audio streaming. It could also be used for something like a backup server. The actual backups are stored on other media than the system running the backup software.  RAID 1: RAID 1 requires 2 drives and is known as mirroring. The exact same data is written to both drives. W...

WIRELESS AUTHENTICATION PROTOCOLS

EAP-TLS (Extensible Authentication Protocol-Transport Layer Security)  requires certificates to be installed on both the wireless clients and the server,  making this one of the most secure implementations of EAP. PEAP (Protected EAP): PEAP only requires the server to have the certificate. PEAP encapsulates the EAP communication in a TLS tunnel. LEAP (Lightweight EAP) : Developed by Cisco, does not require a certificate on either the client or server. Cisco recommends using a stronger version such as EAP-FAST, as LEAP has a known weakness. EAP-FAST (EAP Flexible Authentication via Secure Tunneling):   Developed to replace LEAP. The use of certificates is optional. EAP-TTLS (EAP Tunneled Transport Layer Security):  Needs a certificate on the server, but not the client. The username and password are not sent in plain-text as the transmission is in an encrypted tunnel. PAP can be used for authentication due to the use of Tunneled TLS without the creden...

MALWARE TYPES - PART 3

Rootkits: Are programmed to provide continuous privileged access to a system. This malware remains hidden to avoid detection from an antivirus program. The rootkit will give access to a remote attacker to control items such as system processes. The controller of the rootkit has the ability to change system configuration, spy on users' actions. The detection of such an infection is extremely difficult. The best way to remove a rootkit when detected is to wipe the system and reinstall the operating system and applications. Ransomware: There are two different definitions of the types of ransomware. The first one starts out as scareware. The user clicks on something, a pop-up or web page appears mimicking an antivirus scan. The scan finds infections immediately (even though they don't exist), the number of infections it finds can be anywhere from the teens to the thousands of infections. You click on the button to clean the infections, and you get the notice that this is the Fr...

MALWARE TYPES - Part 2

Logic Bombs: A piece of code that is on a target PC/Sever until it is triggered by an event. That event can be a specific date or time, or when a certain condition is met. The event is specific to what the programmer coded the malware to run. It could be a script that runs every payday, if their name isn't included (meaning they have been laid off/fired) in the payroll report, the malware is triggered to run a predetermined time afterward. Another event could be when the company hires the 250th (just picked a random number for the example), employee. The date is another possibility, launched on a specific date. Worms: Worms are a type of malware that self-replicates. The worm moves through the network consuming bandwidth. Worms take advantage of weaknesses in certain networking protocols.  Worms are known to take advantage of the weakness found in SMBv1, spreading through the network over port 445, Microsoft's file-sharing port. USB flash drives tend to be one of th...

MALWARE TYPES - Part 1

Virus: This is malicious code that attaches to a host program/application. After a user initiates an action such as launching the application. Some viruses deliver the payload immediately, others wait for the virus to replicate. Symptoms vary, the virus may open a backdoor for an attacker, delete files, install a zombie and join the system to a botnet, or cause the system to reboot intermittently. Polymorphic Virus: This type of virus has the ability to change its binary pattern as it replicates or when it is executed. The code is encrypted and uses different encryption after each infection. The ability to change code makes it difficult for an antivirus program to detect this malware. Armored Virus: This type of malware is able to fool antivirus programs as to its true location, making the antivirus believe it is located in one area while being located in a completely different area. Armored viruses use obfuscated code making it difficult to reverse engineer. Trojans: Troja...

LINUX CLI COMMANDS

Here are the Linux commands that you will need to know for the exam: cd: change directory - Allows a user to change between directories chmod: Changes the permissions on the files listed chown: Allows you to change group & user of a file cp: copy - Allows a user to make a copy of a file grep: Search feature to look for a string of text head: outputs the first 10 lines of a file locate: this is the find command, used to locate a file logger: writes input to the local system log or to a remote syslog server ls: Shows the user a list of the files in the current directory man: manual - Will show all the information about a particular command mkdir: make directory - Allows a user to make a new folder or directory mv: move - Allows a user to move a file to another directory or folder passwd: changes the users' password ps: Allows the user to see the processes running on the PC/Server pwd: Allows a user to know the name of the directory in whic...

LINUX PERMISSIONS

Linux permission attributes: r (read)                                                        View file content w (write)                                                     Modify file content x (execute)                                                  Run a file (if it's an executable program & is combined                                                                     with the read attribute) An example of ...